Enterasys X-Pedition XSR CLI Specifikace Strana 554

  • Stažení
  • Přidat do mých příruček
  • Tisk
  • Strana
    / 684
  • Tabulka s obsahem
  • KNIHY
  • Hodnocené. / 5. Na základě hodnocení zákazníků
Zobrazit stránku 553
Remote Peer ISAKMP Protocol Policy Mode Commands
14-100 Configuring the VPN
Syntax
crypto isakmp peer_address subnet-mask
Syntax
Thenoformofthiscommandremovespoliciesfromaremotepeer:
no crypto isakmp peer peer_address subnet-mask
Mode
Globalconfiguration:XSR(config)#
Next Mode
RemotePeerISAKMPprotocolpolicyconfiguration:XSR(config-isakmp-peer)#
Example
ThefollowingexamplesetstheremotepeersIKEpolicies:
XSR(config)#crypto isakmp peer 192.168.57.9 255.255.255.255
XSR(config-isakmp)#
config-mode
ThiscommandsetsthelocalIKEModeConfigurationrole.WhilenotofficiallyanIETFstandard,
configmodeisthedefacto standardforassigningIPaddresseswithinIKE.
InternetKeyExchange(IKE)ModeConfiguration,asimplementedbymanyvendors,allowsa
gatewaytodownloadanIPaddress(andothernetworklevel
configuration)totheclientaspartof
IKEnegotiation.Usingthisexchange,thegatewaygivesIPaddressestotheIKEclienttobeused
asaninnerIPaddressencapsulatedunderIPSec.ThismethodprovidesaknownIPaddressforthe
clientthatcanbematchedagainstIPSecpolicy.
Whenconfigured
asaModeConfiggateway,theXSRallocatesanIPaddresstoapeermrequesting
itandwhenconfiguredasaclient,theXSRrequestsan IPaddressfromthegateway.
Syntax
config-mode {client | gateway}
Syntax of the “no” Form
ThenoformofthiscommandresetsIKEconfigurationmodetothedefault:
no config-mode
peer_address
PeerʹsIPaddressorIPsu bnettowhichthepolicywillbeattached.
subnet-mask
Valueusedwiththepeeraddress.
client
ActasaConfigurationModeclientwiththispeer.
gateway
ActasaConfigurationModeserverwiththispeer.
Zobrazit stránku 553
1 2 ... 549 550 551 552 553 554 555 556 557 558 559 ... 683 684

Komentáře k této Příručce

Žádné komentáře